Cybersecurity Daily: News & Threats
(00:00:00) Record Patch Tuesday: HTTP.sys Zero-Day, BitLocker Bypass & ServiceNow Breach (00:00:32) Three Zero-Days — CTFMON, HTTP.sys, BitLocker (00:01:39) AI Exploit Generation Shrinks Patch Window (00:02:24) ServiceNow Breach — Silent Disclosure Problem (00:03:19) Credential Exposure and What to Check Now (00:03:58) What Enterprises Must Do Now Microsoft has just released the largest Patch Tuesday in its 23-year history, covering up to 208 vulnerabilities — and three of them are confirmed, actively exploited zero-days that demand immediate action across every enterprise environment. The critical trio: an unauthenticated HTTP.sys remote code execution flaw granting kernel-mode access on internet-facing Windows servers; CVE-2026-45586, a CTFMON privilege escalation that elevates local attackers straight to SYSTEM; and CVE-2026-50507, a BitLocker volume master key bypass that undermines full-disk encryption as an offline defence. All three are in active exploitation. This is emergency patching territory. Making the response window even tighter: large language models can now reverse-engineer patches and generate functional exploits within hours of public release. The old assumption of weeks between patch and weaponised exploit is gone. Meanwhile, ServiceNow confirmed a separate breach of its customer data between June 2–3. Attackers exploited an unauthenticated Scripted REST API endpoint — disabled by a single misconfigured parameter — to query IT tickets and harvest embedded credentials across more than 8,000 enterprise instances. The platform was patched June 5; the advisory appeared June 9, behind a customer-only portal. That four-day gap may already have organisations running behind on GDPR, HIPAA, and SEC notification clocks. In this episode: what to patch first, how to assess your ServiceNow exposure, why the monthly patch cycle no longer fits the threat environment, and the specific actions security teams should take in the next 24 hours. This episode includes AI-generated content.
50 episodes
Comments
0Be the first to comment
Sign up now and become a member of the Cybersecurity Daily: News & Threats community!